What is your network topology?
Anti-virus software won't help.
Do you have hardware firewall between server and the wicked outside world?
If so, and it is configured correctly, this is most likely an inside job.
--
Newell White
--
http://www.goldwatches.com/
http://www.jewelerslounge.com/
"Newell White" <Newel...@discussions.microsoft.com> wrote in message
news:D35907B2-F92A-4CBA...@microsoft.com...
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
On Mon, 10 Sep 2007, James Matthews wrote:
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
On Mon, 10 Sep 2007, James Matthews wrote:
You really need to look hard and every possible point of entry. form
existing users to an outside attacker. here are some basic questions to
ask yourself:
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
On Mon, 10 Sep 2007, James Matthews wrote:
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
On Mon, 10 Sep 2007, James Matthews wrote:
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
On Mon, 10 Sep 2007, James Matthews wrote:
*is there a hardware firewall between you and the internet? eg are you on
a private address space?
*audit every account and group membership.
*audit every possbile place to hide startup scripts and excutables, both
in the registry and start menu
*increase event logging to FULL, eg: in secpol.msc check both boxes on all
audit policys
*run both nbtstat and netstat and investigate all conntections.
*consider, having every user reset his/her passwords, and reset all
service accounts. and old or temp accounts reset or disable
That should give you a pretty good start.
-Nex6
On Mon, 10 Sep 2007, James Matthews wrote:
Nex6,
You have definitely replied.
--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html